Количество 7
Количество 7
GHSA-6r8x-57c9-28j4
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
CVE-2026-59199
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
CVE-2026-59199
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
CVE-2026-59199
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
CVE-2026-59199
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public ima ...
SUSE-SU-2026:3084-1
Security update for python-Pillow
SUSE-SU-2026:3268-1
Security update for python-Pillow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6r8x-57c9-28j4 Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
CVE-2026-59199 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-59199 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-59199 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-59199 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public ima ... | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
SUSE-SU-2026:3084-1 Security update for python-Pillow | 18 дней назад | |||
SUSE-SU-2026:3268-1 Security update for python-Pillow | 8 дней назад |
Уязвимостей на страницу